Most FCA-regulated firms use external compliance support at some point. Smaller payment institutions, e-money institutions, cryptoasset firms, consumer credit lenders and investment firms rarely carry the full range of specialist capability in-house, and larger firms use external support for peak workloads, independent review and regulator-facing projects.
The difficulty is that "compliance consultant" describes a very wide range of work, delivered at very different levels of quality. This article sets out what the role covers, how engagements are typically structured and priced, what the FCA expects where compliance activity is outsourced, and the questions to ask before appointing anyone.
What an FCA compliance consultant does
The work divides into four broad categories.
Authorisation and permissions. Preparing FCA applications, including the regulatory business plan, financial projections, governance maps, policy suite and Connect submission, then managing case officer correspondence through to determination. This also covers variations of permission, change in control notifications and cancellations. See our step by step guide to the FCA authorisation process.
Ongoing compliance support. Acting as an external resource to the compliance function: maintaining the policy suite, running the compliance monitoring programme, preparing board and committee reporting, tracking regulatory change, supporting regulatory returns and advising on live business questions as they arise.
Independent review and assurance. Compliance audits, financial crime framework reviews, safeguarding and client asset reviews, permissions reviews, Consumer Duty assessments, and readiness work ahead of an FCA visit or a skilled person review under section 166.
Remediation and regulator engagement. Responding to Dear CEO letters, supervisory information requests, voluntary requirements, past business reviews and enforcement-adjacent workstreams.
When firms appoint one
There are recognisable trigger points.
Applying for authorisation. First-time applicants routinely underestimate the evidential standard. Incomplete applications are the main cause of extended assessment periods.
Growth beyond the existing framework. New products, new customer segments, new jurisdictions or agent networks create obligations the existing framework was not designed for.
Supervisory contact. A Dear CEO letter, a data request, a thematic review or an FCA visit tends to expose whether documentation reflects practice.
Key person departure. The loss of a compliance officer or MLRO leaves an accountability gap that must be filled quickly.
Transaction activity. Change in control, acquisitions and investment rounds require regulatory due diligence and FCA notification.
Audit or assurance requirements. Safeguarding audits, client money audits and internal audit findings frequently generate remediation programmes.
Engagement models and cost
Three structures dominate the market.
| Model | Typical use | How it is priced |
|---|---|---|
| Fixed-fee project | Authorisation applications, VoPs, change in control, policy suite build | Single fee against a defined deliverable and defined assumptions |
| Retained support | Ongoing compliance resource, monitoring, board reporting | Monthly fee against an agreed hour allocation or service schedule |
| Day rate or review | Compliance audits, financial crime reviews, s166 readiness, remediation | Day rate, or fixed fee for a scoped review with a written report |
Price alone is a poor signal. What matters is the scope definition: what is included, what is expressly excluded, who performs the work, what happens when the FCA raises follow-up questions, and whether case officer correspondence sits inside or outside the fee. A low headline fee with narrow scope frequently costs more once the application enters detailed assessment.
What the FCA expects when compliance is outsourced
Using an external provider does not transfer accountability. Under SYSC, a firm remains fully responsible for discharging all of its obligations, and outsourcing must not impair the quality of internal control or the FCA's ability to supervise the firm.
Practically, that means:
- A written agreement setting out the services, standards and responsibilities.
- A named senior manager inside the firm who owns the relationship and the underlying obligation. Under SM&CR the relevant prescribed responsibility cannot be delegated to a third party.
- Oversight of the provider's performance, evidenced rather than assumed.
- Access and audit rights, and appropriate data protection and confidentiality terms.
- An exit plan, so that the firm can bring the activity back in-house or move provider without disruption.
Our guides to outsourcing obligations for payment institutions and EMIs and third party outsourcing due diligence under SYSC 8 set out the requirements in detail.
How to choose
Sector-specific authorisation experience. Ask how many applications the team has taken through determination in your specific permission set within the last twenty-four months, and what the outcomes were. Payment services, e-money, cryptoassets, consumer credit and MiFID investment business each carry different evidential expectations.
Who does the work. Establish whether the individual in the pitch is the individual who will draft the business plan and speak to the case officer, or whether delivery passes to a junior team.
Regulator engagement track record. Direct experience of case officer correspondence, information requests and supervisory meetings is materially different from policy drafting.
Depth of the policy output. Generic template suites are visible to case officers and are a common cause of challenge. Documentation must reflect the firm's actual operating model, systems and risk profile.
Independence. Where the engagement is an audit or independent review, the provider should not be reviewing its own prior work without disclosure.
Continuity. Authorisation projects run for months and supervisory relationships run for years. Team stability matters.
Professional indemnity cover and contractual terms. Confirm cover levels, liability caps, and the position on work product ownership.
Questions worth asking before you sign
- What exactly is in scope, and what is expressly out of scope?
- What are your assumptions on the number of FCA question rounds included?
- Who is the named lead, and what proportion of the work will they personally perform?
- What does the deliverable look like? Ask for a redacted example.
- How do you handle a change of regulatory position mid-project?
- What are the notice terms, and what happens to work product on exit?
- How will you evidence the work so that it stands up to supervisory review?
Where value is created and lost
Value is created where external support brings pattern recognition: knowing how a case officer will read a business plan, which control gaps consistently attract challenge, what a proportionate framework looks like for a firm of a given size, and how to close a finding in a way that does not create a new one.
Value is lost where documentation is produced without reference to how the firm actually operates. A policy suite that describes controls the firm does not perform is worse than no policy suite, because it evidences a governance failure rather than a documentation gap.
About Regulatory Counsel
Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.
Our compliance support work covers FCA authorisation and variation of permission applications, retained compliance support, compliance monitoring programmes, policy framework design, financial crime and safeguarding reviews, Consumer Duty implementation, regulator correspondence and remediation programmes.
Contact our regulatory team at info@regulatorycounsel.co.uk.
This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.
Frequently Asked Questions
Typical work covers authorisation and permissions applications, ongoing compliance support such as monitoring and board reporting, independent reviews and audits, and remediation or regulator engagement following supervisory contact.
Engagements are usually priced as a fixed fee for a defined project such as an authorisation application, a monthly retainer against an agreed hour allocation, or a day rate for review work. Scope definition matters more than headline price.
A firm can outsource compliance activity but not accountability. Under SYSC the firm remains fully responsible, the arrangement must not impair internal control or FCA supervision, and a named senior manager must retain ownership of the obligation.
No. Prescribed responsibilities sit with approved senior managers within the firm and cannot be transferred to an external provider. The senior manager must be able to demonstrate reasonable steps, including oversight of the provider.
Common triggers include an authorisation or variation of permission application, growth into new products or jurisdictions, supervisory contact such as a Dear CEO letter or information request, departure of a compliance officer or MLRO, and transaction activity requiring change in control notification.
Sector-specific authorisation experience with recent outcomes, who personally performs the work, direct regulator engagement experience, the depth and bespoke quality of deliverables, independence where the work is an audit, and contractual terms including liability and exit.
